CVE-2008-5052

EUVD-2008-5031
The AppendAttributeValue function in the JavaScript engine in Mozilla Firefox 2.x before 2.0.0.18, Thunderbird 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13 allows remote attackers to cause a denial of service (crash) via unknown vectors that trigger memory corruption, as demonstrated by e4x/extensions/regress-410192.js.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
10 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:N/C:C/I:C/A:C
Base Score
CVSS 3.x
EPSS Score
Percentile: 95%
Affected Products (NVD)
VendorProductVersion
mozillafirefox
2.0 ≤
𝑥
< 2.0.0.18
mozillaseamonkey
1.0 ≤
𝑥
≤ 1.1.13
mozillathunderbird
2.0 ≤
𝑥
< 2.0.0.18
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
firefox
dapper
Fixed 1.5.dfsg+1.5.0.15~prepatch080614h-0ubuntu1
released
gutsy
Fixed 2.0.0.18+nobinonly-0ubuntu0.7.10
released
hardy
Fixed 2.0.0.18+nobinonly-0ubuntu0.8.04.1
released
intrepid
dne
firefox-3.0
dapper
dne
gutsy
ignored
hardy
Fixed 3.0.4+nobinonly-0ubuntu0.8.04.1
released
intrepid
Fixed 3.0.4+nobinonly-0ubuntu0.8.10.1
released
iceape
dapper
dne
gutsy
ignored
hardy
dne
intrepid
dne
icedove
dapper
dne
gutsy
dne
hardy
dne
intrepid
dne
iceweasel
dapper
dne
gutsy
dne
hardy
dne
intrepid
dne
mozilla-thunderbird
dapper
Fixed 1.5.0.13+1.5.0.15~prepatch080614h-0ubuntu0.6.06.1
released
gutsy
dne
hardy
dne
intrepid
dne
seamonkey
dapper
dne
gutsy
dne
hardy
Fixed 1.1.15+nobinonly-0ubuntu0.8.04.2
released
intrepid
Fixed 1.1.15+nobinonly-0ubuntu0.8.10.2
released
thunderbird
dapper
dne
gutsy
Fixed 2.0.0.18+nobinonly-0ubuntu0.7.10.1
released
hardy
Fixed 2.0.0.18+nobinonly-0ubuntu0.8.04.1
released
intrepid
Fixed 2.0.0.18+nobinonly-0ubuntu0.8.10.1
released
xulrunner
dapper
dne
gutsy
Fixed 1.8.1.18+nobinonly.b308.cvs20090331t155113-0ubuntu0.7.10.1
released
hardy
Fixed 1.8.1.18+nobinonly.b308.cvs20090331t155113-0ubuntu0.8.04.1
released
intrepid
Fixed 1.8.1.16+nobinonly-0ubuntu1
released
xulrunner-1.9
dapper
dne
gutsy
ignored
hardy
Fixed 1.9.0.4+nobinonly-0ubuntu0.8.04.1
released
intrepid
Fixed 1.9.0.4+nobinonly-0ubuntu0.8.10.1
released
Common Weakness Enumeration